Crypto Warning: Bonk.fun Domain Hack Exposes Solana Traders To Wallet Drain

bitcoinistPublicado em 2026-03-14Última atualização em 2026-03-14

Resumo

Crypto platform Bonk.fun suffered a domain hijacking attack on March 12, 2026, exposing users to a wallet-draining exploit. Hackers injected a malicious script on the website, prompting users to sign a fake "Terms of Service" agreement, which, when approved, allowed the attackers to steal funds. The team confirmed that only users who interacted with the fraudulent prompt after the hack were affected, and losses were reported as minimal. The breach was attributed to a Web2 infrastructure failure rather than a smart contract exploit. This incident highlights the growing threat of approval-phishing and domain hijacking attacks in the crypto space, underscoring the need for heightened user caution and improved security practices.

A Crypto platform confirmed that their main domain website had been hacked, which exposed its users to a wallet draining exploit.

A No-Fun Crypto Hijack

It is a truth universally acknowledge that, no matter the size of a global geopolitical crisis, hackers will continue to ravage through the crypto market. This time, the victim was memecoin issuance platform Bonk.fun. In a March 12 post on the social network X, Tom (@SolportTom), one of its operators, warned the users not to interact with the domain “until further notice”, as hackers had injected a crypto wallet drainer on it:

The official X account of the Solana token launchpad, backed by Raydium and the BONK community, also announced the hack and echoed Tom’s striking warning:

Who Is Affected And How

Tom explained that the phishing scam set up a fake “Terms of Services” (TOS) signature prompt which, when signed, allowed the drainer to move the unaware user’s funds. According to Tom, the only users compromised were the ones who interacted with the fake TOS. He clarified that neither previously connected users nor traders of bonk fun tokens on third-party terminals were affected. He also assured that the security breach was spotted early so “the losses are minimal to date”:

This is not a Raydium or BONK smart contract exploit, but the case of a Web2 infrastructure failure that bled directly into Web3. This type of domain hijacking and phishing drainer scripts work by the attackers taking over the frontend and presenting normal-looking prompts that abuse wallet approvals.

A Pattern Of Exploited Vulnerabilities

In recent years, approval-phishing and “fake UI” attacks have stolen billions of dollars: one Chainalysis investigation reported the amount of $14 billion in on-chain scam inflows in 2025, with projections pointing above the $17 billion as more wallets continued to be identified.

As scam revenues grow and AI‐driven impersonation scales, crypto security in 2026 is less about the perfect code and more about defending everything around it: from domains to social accounts, employees and users decision-making. In February last year, attackers hijacked Pump.fun’s X account to push a fake PUMP token, as covered by our sister website NewsBTC. Not too long ago, OG trader Sillytuna was drove out of the crypto market after a multimillion-dollar theft that combined online address poisoning and offline violent actions.

The times are testing traders online and offline, both inside and outside the bloc. As the crypto landscape grows more complex, traders would do well to heighten their caution: prefer direct contract interaction or trusted aggregators, and use tools to monitor and regularly revoke token approvals.

SOL’s price trends to the upside on the daily chart. Source: SOLUSDT on Tradingview

Cover image from Perplexity, SOLUSDT chart from Tradingview

Perguntas relacionadas

QWhat was the main security incident that occurred with Bonk.fun?

AThe main domain of Bonk.fun was hacked, and a wallet drainer was injected into the website, exposing users to a phishing scam.

QHow did the wallet drainer on Bonk.fun's compromised domain work?

AThe drainer set up a fake 'Terms of Services' (TOS) signature prompt. When users signed this prompt, it allowed the attacker to move their funds.

QAccording to the article, which users were affected by this security breach?

AOnly users who interacted with the fake TOS message on the compromised Bonk.fun domain after the hack were affected. Previously connected users and those trading on third-party terminals were not compromised.

QWhat type of exploit was this incident classified as, and what was its root cause?

AThis was not a smart contract exploit. It was a Web2 infrastructure failure (domain hijacking) that led to a Web3 phishing attack, where the frontend was compromised to present malicious prompts.

QWhat broader trend in crypto scams does the article mention, and what was a key statistic provided?

AThe article mentions that approval-phishing and 'fake UI' attacks have become a major trend. A Chainalysis investigation reported $14 billion in on-chain scam inflows in 2025, with projections exceeding $17 billion.

Leituras Relacionadas

Coinbase Vice President: The Wars Over Cryptocurrency Regulation Are Over

Coinbase's new Vice President, Ryan VanGrak, declared that regulatory wars in the cryptocurrency sector are over. Since taking office on July 9, 2026, he has shifted the company's approach from litigation and sanctions to focusing on growth and innovation. The industry can now concentrate on development rather than fighting for its right to exist. He highlighted that the Digital Asset Market Clarity Act (CLARITY Act), which aims to establish a clear federal regulatory framework dividing oversight between the SEC and CFTC, has gained significant momentum. This framework is intended to provide proper supervision, investor protection, and maintain U.S. leadership in digital assets. VanGrak's appointment marks a strategic shift from a "wartime" to a "peacetime" advisor, replacing former Chief Legal Officer Paul Grewal, who oversaw major litigation, including a dismissed 2023 SEC lawsuit. With his background at Citadel Securities and the SEC, VanGrak brings deep regulatory and institutional finance expertise as Coinbase expands beyond a simple exchange into a broader financial services provider, offering stocks, futures, prediction markets, and AI tools. For investors, bipartisan support for crypto legislation like the CLARITY Act represents a major shift from the enforcement-focused environment of 2023-2024. Lawmakers are now focused on *how* to regulate crypto, not *if* it should exist. However, risks remain, as the bill's passage is not yet guaranteed.

cryptonews.ruHá 10m

Coinbase Vice President: The Wars Over Cryptocurrency Regulation Are Over

cryptonews.ruHá 10m

Deep Dive into FWA: An Intriguing Experiment Turning NFTs into "On-Chain Gachapon"

A Deep Dive into FWA: The “On-Chain Gacha” Experiment for NFTs Fake World Assets (FWA), created by TokenWorks, introduces an innovative “NFT gacha machine” fully operating on-chain. Users can deposit eligible NFTs paired with ETH (called Backing) to create a Position, acting as a prize pool. Others can then pay a uniform Acquisition Price for a chance to win a random NFT from the pool. The core mechanism features a reverse probability system: Positions with lower Backing have a higher chance of being selected, serving as common prizes, while high-Backing Positions are rare “jackpots.” The acquisition price is calculated based on the harmonic mean of all Backings, keeping entry costs low. When a Position is won, the purchaser must choose: keep the NFT or accept the Standing Bid (85% of the Backing, claimable in ETH or $FWA tokens), returning the NFT to the original depositor. The protocol involves two main roles. Depositors provide liquidity (NFT + ETH), earning a share of fees from each draw, distributed equally per active Position, plus potential $FWA rewards. Purchasers pay to spin the gacha, receiving $FWA rewards for participation. A special “Crown” reward goes to the Position with the highest Backing. The $FWA token has a fixed supply and is initially obtainable only through protocol participation (depositing or purchasing), with external buying disabled early on to reduce sell pressure. Its value is supported by a built-in buy pressure: when purchasers opt for the $FWA settlement on a Standing Bid, the protocol uses the backing ETH to buy $FWA from the market. Revenue for the protocol comes from a 1% fee on each draw, a 1% settlement fee when an NFT is kept, and the 15% discount from Standing Bid settlements (currently allocated to the protocol). The design cleverly blends Uniswap-style liquidity provision, gacha mechanics, and tokenomics to create a novel, self-regulating marketplace for NFT liquidity and engagement.

marsbitHá 25m

Deep Dive into FWA: An Intriguing Experiment Turning NFTs into "On-Chain Gachapon"

marsbitHá 25m

10,000 Scientists Get 1 Year of Free Access: OpenAI Brings the Scientific Research Pipeline into ChatGPT

OpenAI has launched the "ChatGPT for Academic Researchers" program, offering free one-year access to its flagship models for 100,000 university researchers globally, with 10,000 spots available this summer. Selected institutions include prestigious centers like ENS Paris and the IAS at Princeton. The initiative provides an integrated research workspace within ChatGPT, bundling tools like ChatGPT, ChatGPT Work, and Codex, along with expanded Deep Research capabilities, higher usage limits, and specialized tools for life sciences. The suite connects to platforms like Zotero and GitHub, aiming to streamline the entire research workflow from literature review and coding to data analysis and manuscript drafting. OpenAI notes that about 1.3 million people already use ChatGPT weekly for advanced science and math. The program targets building long-term user dependency by embedding these tools into daily research habits. However, access comes with limitations: it does not include API credits or model weights, and eligibility is restricted to verified academic researchers from supported countries. This approach contrasts with Anthropic's "AI for Science" program, which offers API credits but not an integrated workspace. Both companies emphasize preventing misuse by withholding model weights, a point of contention for AI researchers seeking transparency. The core strategy remains clear: provide a powerful, integrated environment to foster user reliance ahead of the post-free period.

marsbitHá 30m

10,000 Scientists Get 1 Year of Free Access: OpenAI Brings the Scientific Research Pipeline into ChatGPT

marsbitHá 30m

What's Going On with Gigadevice? Major Shareholder Cashes Out 44 Billion, Then Announces 20 Billion Buyback

Gigadevice Innovation, a leading Chinese memory chip company, has executed a controversial financial maneuver. The company's controlling shareholder and chairman, Zhu Yiming, sold approximately 44 billion RMB worth of his shares between early May and mid-June 2026, capitalizing on a soaring stock price that peaked at 846.66 RMB on June 29th. Following a subsequent stock crash—plummeting to around 350 RMB in 22 trading days and erasing over 330 billion RMB in market value—Zhu announced a combined "market rescue" plan on July 29th. This plan includes his personal commitment to buy back at least 1 billion RMB in shares and a company proposal to repurchase 1 to 2 billion RMB worth of stock. This sequence of high-selling followed by a low-buying plan has confused and unsettled many of the company's 240,000 retail investors. The stock's dramatic decline was attributed to several factors: the successful IPO of its sister company, Changxin Technologies, which ended Gigadevice's status as a primary investment proxy for the domestic memory sector; a Morgan Stanley report warning of a potential peak in the memory chip cycle; and a severe loss of market confidence triggered by the chairman's massive sell-off. While the sell-off was procedurally compliant, its timing has been criticized. The company's fundamentals appear strong, with preliminary H1 2026 results showing revenue up 177% year-on-year to 11.5 billion RMB and net profit skyrocketing 1099% to 6.9 billion RMB, driven by a boom in memory chips and MCU demand. However, a significant portion (2.05 billion RMB) of this profit came from non-recurring gains like securities investment, and the memory industry is notoriously cyclical. Analysts highlight the company's role in the domestic substitution of niche DRAM and NOR Flash memory, with some maintaining bullish price targets. Yet, the recent events underscore key risks: its fabless model creates dependency on foundries like Changxin, and the chairman's actions have raised serious questions about management's alignment with minority shareholders. The promised buybacks cannot commence until December 13th due to a mandatory six-month cooling-off period following an insider sale, leaving the stock vulnerable in the interim.

marsbitHá 30m

What's Going On with Gigadevice? Major Shareholder Cashes Out 44 Billion, Then Announces 20 Billion Buyback

marsbitHá 30m

Trading

Spot
活动图片